CVE-2020-17516

EUVD-2022-0769
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
apachecassandra
2.1.0 ≤
𝑥
≤ 2.1.22
apachecassandra
2.2.0 ≤
𝑥
≤ 2.2.19
apachecassandra
3.0.0 ≤
𝑥
≤ 3.0.23
apachecassandra
3.11.0 ≤
𝑥
≤ 3.11.9
𝑥
= Vulnerable software versions